Data Processing Addendum
Last updated: · Version 2026-09-27
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between you (the “Customer”) and Ivorn (“Ivorn”), the provider of Omnihorn. It applies wheneverIvorn processes personal data on your behalf, and it takes effect automatically when you accept the Terms — no signature is needed. If you need a countersigned copy, write to legal@unicornfamily.dev.
1. Roles
- For End User data — data sent by the installers of your apps (section 2) — you are the controller and Ivorn is your processor.
- For your account, workspace and billing data, Ivorn is an independent controller, as described in the Privacy Policy. This DPA does not apply to that data.
2. Details of the processing
| Subject matter | Delivering your application builds to End Users and giving you install and update analytics. |
| Duration | For as long as you use Omnihorn, plus the deletion period in section 8. |
| Nature and purpose | Receiving, storing, aggregating and displaying update checks and install/update/uninstall events; logging access to private channels. |
| Data subjects | People who install and run your applications (End Users). |
| Personal data | A random device ID generated by the installer; app, channel and build identifiers; platform and operating-system version; event type and time; for private channels, which channel token was used; and, when an End User uninstalls through the installer and chooses to answer, the reason they pick from a fixed list and an optional short note (up to 200 characters) that they type themselves. IP addresses are not stored in the database; they appear only in reverse-proxy logs. |
| Special categories | None. You must not configure Omnihorn to send special-category data. The uninstall note is free text written by the End User: do not ask End Users to include personal details in it, and treat what you read there as personal data if it identifies anyone. |
3. Ivorn's obligations as processor
Ivorn will:
- process End User data only on your documented instructions — these Terms, this DPA and your configuration ofOmnihorn — unless the law requires otherwise, in which case Ivorn will tell you first where the law allows;
- ensure that everyone authorised to process the data is bound by confidentiality;
- implement the security measures in section 7;
- engage subprocessors only as described in section 5;
- help you, taking into account the nature of the processing, to respond to End Users exercising their rights and to meet your obligations on security, breach notification, impact assessments and prior consultation;
- notify you of a personal data breach as described in section 6;
- delete or return End User data at the end of the service, as described in section 8;
- make available the information needed to demonstrate compliance with this DPA, as described in section 9.
4. Your obligations
You are responsible for having a lawful basis for the processing, for informing your End Users (for example in your application’s privacy notice) and for the lawfulness of your instructions.
5. Subprocessors
You authorise Ivorn to use the subprocessors below. Ivorn imposes data-protection obligations on each of them that are no less protective than this DPA, and remains responsible for their performance.
Current subprocessors
| Provider | Purpose | Location | Data involved |
|---|---|---|---|
| Self-hosted infrastructure (operated by us) | Application servers, PostgreSQL databases, Redis, message queue, and MinIO object storage for build files; reverse proxy and log system. | [[PLACEHOLDER: country where the current self-hosted server is located]] | All service data |
| Resend | Transactional email delivery (sign-in links, quota warnings). | USA | Customer email address, email content |
| WayForPay | Card payments for buyers in Ukraine. | Ukraine | Payer email, order and payment data |
| Sentry | Crash and error monitoring for the Omnihorn installer. Listed ahead of use: not yet enabled for any compiled installer. | USA / European Union | Error messages, stack traces, the same random device ID sent with update checks — no name, email or IP address |
| Tailscale | Private network used by our staff to reach the administration site and by our installer build machine to reach our infrastructure. | [[PLACEHOLDER: Tailscale processing location — check its DPA]] | Network connection metadata of our own devices; service traffic is end-to-end encrypted |
| GitHub (including GitHub Container Registry) | Hosting of our own source code, build pipeline and container images. | USA | None of your data or End User data |
Planned — will be added before launch
These providers are not used today. They will be added when the corresponding change goes live, with notice as described below.
| Provider | Purpose | Location | Data involved |
|---|---|---|---|
| Hetzner | Virtual servers replacing the current self-hosted server. | Germany / Finland | All service data |
| Cloudflare | DNS, content delivery of build files, and R2 object storage. | Global network; USA | Build files, download requests (IP address, user agent) |
| Paddle | Merchant of record for purchases outside Ukraine: checkout, tax, invoicing, refunds. | United Kingdom | Buyer name, email, billing address, country, tax ID, payment data |
Changes. Ivorn will update this list and notify customers by email or in the dashboard at least [[PLACEHOLDER: subprocessor change notice period — e.g. 30 days]] before a new subprocessor starts processing End User data. You may object on reasonable data-protection grounds by writing to privacy@unicornfamily.dev within that period; if we cannot address the objection, you may cancel the affected service and receive a pro-rata refund of prepaid fees for it.
6. Personal data breaches
Ivorn will notify you without undue delay, and in any case within [[PLACEHOLDER: breach notification window — e.g. 72 hours]], after becoming aware of a personal data breach affecting End User data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where not all of this is available at once, Ivorn will provide it in phases.
7. Security measures
The technical and organisational measures in place today are:
- TLS for all public traffic to the dashboard, API and update service.
- Every build manifest signed with a per-app Ed25519 key and verified by the installer before any file is applied; each downloaded file verified against its SHA-256 hash.
- App signing keys encrypted at rest with a master key, or optionally held under a cloud key-management service.
- Channel tokens and API keys stored only as SHA-256 hashes; private channels can also require a password, stored as an argon2id hash.
- Per-workspace isolation: every query is scoped to the workspace, and a workspace can only reference stored files it uploaded itself; download links are short-lived and signed.
- The update service reads only the application database; account and billing data sit in a separate database it cannot reach.
- Staff accounts use argon2id-hashed passwords with lock-out after repeated failures, separate credentials from customer accounts, role-based permissions and an audit log of every administrative action. The administration site is reachable only over a private network.
- Uploads may be scanned for malware before they are published.
Ivorn may improve these measures over time but will not materially reduce the overall level of protection.
8. Deletion at the end of the service
At the end of the service, or earlier on your written request to privacy@unicornfamily.dev, Ivorn deletes the End User data it holds for you from its active systems, unless the law requires it to keep it. Deleting an app in the dashboard deactivates it but does not yet purge its End User data automatically, and automatic retention schedules for analytics events and access logs have not been introduced; until they are, that data is kept until it is deleted on request or the account is closed. Copies in logs are removed as those logs are rotated.
9. Audits
On written request, not more than once a year unless a breach or a supervisory authority requires more, Ivornwill answer reasonable written questions about its compliance with this DPA and provide relevant documentation. Any on-site audit must be agreed in advance, at your cost, and subject to confidentiality.
10. International transfers
Ivorn operates from Ukraine, and subprocessors may process data in the European Union, the United Kingdom and the United States. Where End User data from the EEA, the UK or Switzerland is transferred to a country without an adequacy decision, the parties rely on [[PLACEHOLDER: SCC module/version and transfer mechanism]], which are incorporated into this DPA by reference, with Ivorn as data importer.
11. Liability and precedence
Liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms on the processing of End User data, this DPA prevails; the standard contractual clauses, where they apply, prevail over both.